opifex/symfony
65.7
Adequate · 21 September 2026
6.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This is a Symfony-based backend service implementing a CQRS architecture to manage user accounts and handle authentication via JWT tokens. It exposes RESTful APIs for account lifecycle operations, including creation, retrieval, and administrative controls, while supporting PayPal webhook integrations for payment events. The system is built with a strong emphasis on domain-driven design, featuring robust infrastructure for message handling, observability, and security.
How it got here
2023 — Initial Symfony scaffolding and core infrastructure
17 changes.
This period established the foundational architecture of the application by scaffolding a Symfony 8.1 project with Docker, CI/CD tooling, and static analysis configurations. It implemented the core presentation layer, including CQRS-based controllers for authentication and admin account management, alongside essential infrastructure like health checks and email templates.
2024–2025 — Core domain and infrastructure foundation
27 changes.
This period focused on establishing the foundational architecture for the account management system, including the domain model, Doctrine persistence layer, and Symfony infrastructure components. It introduced core services for authentication, messaging, and logging, while implementing strict validation and error handling mechanisms across the HTTP and application layers.
2026 — Core account management and security infrastructure
18 changes.
This period focused on establishing the foundational architecture for account management and security, introducing domain contracts, JWT-based authentication, and password hashing. It also implemented essential application-layer command and query handlers for account lifecycle operations alongside infrastructure components for observability, caching, and event handling.
Features
Added Doctrine Migrations template for generating migration classes
A new Twig template (migration.php.twig) has been added to the DoctrineMigrationsBundle presentation layer. This template provides the standard PHP structure for Doctrine DBAL migrations, including the AbstractMigration base class, up/down method signatures, and namespace/class placeholders, enabling the generation of properly formatted migration files.
src/Presentation/Resource/Template/bundles/DoctrineMigrationsBundle · high confidence
Added Doctrine mapping for the Account entity
Introduced the Doctrine ORM mapping for the Account entity, defining the 'account' table structure with fields for email, password, locale, roles, and status. The mapping includes a unique constraint on the email address (excluding soft-deleted records), lifecycle callbacks to automatically update the 'updated\_at' timestamp, and support for optimistic locking via a version column.
src/Infrastructure/Doctrine/Mapping · high confidence
Added GitHub Actions and TeamCity report formats for PHP\_CodeSniffer
The system now supports two new output formats for PHP\_CodeSniffer analysis results. The new PhpcsGithubReport class formats linting errors and warnings as GitHub Actions workflow commands, enabling direct integration with GitHub's code scanning and pull request annotations. The new PhpcsTeamcityReport class formats results using TeamCity service messages, allowing CI/CD pipelines running on TeamCity to display inspection types and individual issues with proper severity and fixability metadata.
config/markup/Reports · high confidence
Added JSON-based login authenticator with rate limiting
A new JsonLoginAuthenticator class has been introduced to handle JSON payload authentication requests. This component enforces rate limiting on login attempts by tracking both the email/IP combination and the IP address alone, throwing a TooManyRequestsHttpException if limits are exceeded. It supports interactive authentication flows and creates standard username/password tokens upon successful validation.
src/Infrastructure/Security/Authenticator · high confidence
Added PHP code quality configuration for PHPCS and PHPStan
Introduced configuration files for PHP\_CodeSniffer (phpcs.xml) and PHPStan (phpstan.neon) to enforce coding standards and static analysis. The PHPCS configuration applies the PSR12 standard with additional rules for code structure, naming conventions, and forbidden functions, while excluding specific Doctrine mapping and migration directories from line-length checks. The PHPStan configuration sets the analysis level to 'max' and includes extensions for deprecation rules, Doctrine, PHPUnit, strict rules, and Symfony integration.
config/markup · high confidence
Added PayPal webhook request parser
A new PayPalRequestParser class has been introduced to handle incoming PayPal webhook requests. It validates that requests are POST and JSON, verifies the webhook token against a secret, and delegates payload conversion to the existing PayPalPayloadConverter, ensuring proper parsing and error handling for remote events.
src/Infrastructure/Adapter/PayPal/Webhook · high confidence
Added Symfony console and PHPUnit entry-point scripts
The project now includes executable shell scripts in the bin directory to bootstrap the application and run tests. bin/console initializes the Symfony Kernel and exposes the console application for command-line interactions, while bin/phpunit delegates execution to the PHPUnit library installed in vendor, enabling standard test execution.
bin · high confidence
Added UUID v7 identity generator implementation
The application now includes a concrete implementation of the UUID identity generator interface, located in src/Infrastructure/Uuid. This new UuidIdentityGenerator class utilizes Symfony's Uuid component to generate version 7 UUIDs, providing a standardized method for creating unique identifiers within the infrastructure layer.
src/Infrastructure/Uuid · high confidence
Added ValidationFailedException for HTTP 422 responses
A new ValidationFailedException class has been introduced in the Messenger infrastructure to handle validation errors. This exception extends RuntimeException and is configured to automatically return an HTTP 422 status code. It stores the specific constraint violations, allowing consumers to access the detailed validation failure information via the getViolations method or by using the fromViolations factory method.
src/Infrastructure/Messenger/Exception · high confidence
Added account data fixtures for development and testing
A new Doctrine fixture class (AccountFixture) has been introduced to seed the database with sample account data. This fixture creates an admin account, a standard user account, and ten additional random user accounts, all using a consistent password hash and realistic timestamps. This enables developers and testers to quickly populate the application with valid user data for local development and automated testing environments.
src/Infrastructure/Doctrine/Fixture · high confidence
Added application queries to retrieve account details by ID and for the current signed-in user
New query handlers and DTOs have been added to the application layer to support fetching account information. The \GetAccountById\ query allows retrieving an account's details (ID, email, locale, status, roles, and timestamps) by a specific UUID, while the \GetSigninAccount\ query retrieves the same set of details for the currently authenticated user by resolving their identifier from the authorization token storage. Both queries use Symfony Messenger for handling and return structured JSON-serializable results.
src/Application/Query/GetAccountById · high confidence
Added cache-backed JWT access token revocation
A new \JwtAccessTokenRevokerCache\ implementation has been added to the infrastructure layer to handle JWT access token revocation using a PSR-6 cache pool. This component allows the system to track revoked tokens by storing their identifiers in the cache with a time-to-live (TTL) derived from the token's expiration time, enabling efficient checks via the \isRevoked\ method without requiring a database lookup for every request.
src/Infrastructure/Cache · high confidence
Added domain-specific HTTP exception classes for account operations
Introduced four new exception classes in the account domain to provide structured error handling with automatic HTTP status mapping: AccountAlreadyExistsException (409 Conflict) for duplicate email addresses, AccountInvalidActionException (422 Unprocessable Entity) for invalid account actions, AccountNotFoundException (404 Not Found) for missing accounts, and AccountRevisionConflictException (409 Conflict) for revision conflicts. These exceptions extend RuntimeException and use Symfony's WithHttpStatus attribute to ensure consistent API responses.
src/Domain/Account/Exception · high confidence
Added email notification support for new account registrations
The system now sends a personalized welcome email when a new account is created. This is implemented via a new \AccountRegisteredEventHandler\ that listens for the \AccountRegisteredEvent\, translates the email subject based on the user's locale, and renders the \@emails/account.registered.html.twig\ template. A new \TemplatedEmailNotification\ class bridges Symfony's TemplatedEmail with the Notifier component to ensure the email is correctly formatted and sent to the registered user.
src/Infrastructure/Notifier · high confidence
Added email templates for account registration
New Twig templates have been added to the email presentation layer to support account registration notifications. A new base layout (default/body.html.twig) provides the HTML structure for emails, and a specific template (account.registered.html.twig) extends this layout to display a confirmation message containing the user's email address upon successful account creation.
src/Presentation/Resource/Template/emails · high confidence
Added health status endpoint
A new GET /health endpoint has been introduced to allow users to check the current health status of the application. This controller exposes the health status via a JSON response, integrating with the existing query bus to retrieve the status information.
src/Presentation/Controller/Health · high confidence
Added health status query capability
Introduced a new application-layer query structure for retrieving system health status. This includes a query object, a result DTO that serializes the health check status to JSON, and a message handler that processes the query by invoking the domain Healthcheck service and returning a success response.
src/Application/Query/GetHealthStatus · high confidence
Added infrastructure adapters for HTTP responses and template rendering
Introduced two new infrastructure components: an HTTP client adapter that fetches JSON data from an external service (configured via the HTTPBIN\_URL environment variable) and a Twig-based template renderer. These classes implement application contracts to provide concrete implementations for retrieving external API responses and rendering views, handling errors by wrapping underlying exceptions in domain-specific failure exceptions.
src/Infrastructure/Adapter/Kennethreitz · high confidence
Added infrastructure components for domain event collection and failed message monitoring
This change introduces two new classes in the Messenger infrastructure layer. The \DomainEventCollector\ provides a mechanism to collect, release, and reset domain events within the current request scope, implementing \ResetInterface\ to ensure clean state between requests. The \FailedMessageCounter\ implements the application's \FailedMessageCounterInterface\ by delegating to the Symfony Messenger failed transport, allowing the application to query the number of messages currently in the failure queue.
src/Infrastructure/Messenger · high confidence
Added message middleware for correlation IDs, validation, and domain event handling
The application now includes three new Symfony Messenger middleware components to enhance message processing. The CorrelationIdMiddleware automatically attaches or propagates correlation IDs to messages for better tracing. The MessageValidationMiddleware validates incoming messages using the Symfony Validator before they are processed, throwing a ValidationFailedException if constraints are violated. The DomainEventMiddleware collects domain events generated during message handling and publishes them via the EventMessageBus after the message handler completes, ensuring events are only published if the handler succeeds.
src/Infrastructure/Messenger/Middleware · high confidence
Added password and token-based user authentication models
Introduced new infrastructure classes to support two distinct authentication mechanisms: password-based login and token-based access. The PasswordAuthenticatedUser class now stores user credentials and roles, while the PasswordAuthenticatedUserChecker enforces account activation status by blocking login attempts for disabled accounts. Additionally, the TokenAuthenticatedUser class provides a structure for managing token identifiers, expiration times, and associated user roles.
src/Infrastructure/Security/AuthenticatedUser · high confidence
Added public entry point for the application
A new public/index.php file has been added to serve as the entry point for the application. It initializes the App/kernel using the runtime loader, configuring the kernel based on the APP\_ENV and APP\_DEBUG environment variables.
public · high confidence
Added query support for retrieving accounts by criteria
Users can now retrieve a paginated list of accounts filtered by email and status. This change introduces the GetAccountsByCriteriaQuery, its handler, and the result structure, which maps account details (ID, email, locale, status, roles, and timestamps) into a JSON-serializable format with pagination metadata.
src/Application/Query/GetAccountsByCriteria · high confidence
Added request payload value resolver for strict DTO binding
A new Symfony value resolver has been introduced to automatically deserialize request bodies into strongly-typed Data Transfer Objects (DTOs). This component enforces strict validation by rejecting unknown request parameters and ensuring type correctness, throwing specific exceptions when extra attributes are present or when data fails to normalize to the expected type.
src/Infrastructure/HttpKernel/ValueResolver · high confidence
Admin account management API endpoints
This change introduces a set of new REST API controllers in the Presentation layer for managing user accounts, restricted to users with the ROLE\_ADMIN permission. The endpoints allow administrators to create new accounts (POST /account), retrieve a single account by ID (GET /account/{id}), list accounts filtered by criteria with pagination (GET /account), update account details like email, password, or locale (PATCH /account/{id}), block and unblock accounts (POST /account/{id}/block, POST /account/{id}/unblock), and delete accounts (DELETE /account/{id}). Each controller is wired to its corresponding Application command or query handler and includes OpenAPI documentation for request/response schemas.
src/Presentation/Controller/Account · high confidence
Automatic correlation ID injection for outbound HTTP requests
Outbound HTTP requests now automatically include an X-Correlation-Id header to improve observability and request tracing. This is implemented via a new CorrelationIdHttpClient decorator that wraps the standard Symfony HTTP client, injecting a correlation ID provided by the new CorrelationIdProvider (which generates a UUID v4 if one is not already set). The provider also supports resetting the ID per request context.
src/Infrastructure/HttpClient · high confidence
Enhanced logging with authorization, correlation, and sensitive data protection
The application now includes several Monolog processors to improve log quality and security. The AuthorizationProcessor automatically attaches the current user's identifier and roles to log entries when a security token is present. The CorrelationIdProcessor injects a unique correlation ID into logs to facilitate request tracing. The IntrospectionProcessor adds source file and line number information to help developers locate the origin of log messages. Additionally, the SensitiveDataProcessor, supported by a new SensitiveDataProtector, automatically masks sensitive fields like emails and passwords in log contexts to prevent accidental data exposure.
src/Infrastructure/Monolog · high confidence
Initial Docker configuration for development and production environments
This change introduces the foundational Docker configuration files for the application, establishing the runtime environment for both development and production. It includes PHP settings for development (with Xdebug) and production (with OPcache JIT), an entrypoint script that manages environment-specific setup and commands (application, messenger, migration, quality), Nginx configuration for handling requests and logging, Supervisor configurations for managing Nginx, PHP-FPM, and background messenger workers (domain-events, notifier-emails, webhook-events, scheduler-tasks), and PHP-FPM pool settings.
config/docker · high confidence
Initial Symfony application configuration scaffold
The application now includes the standard Symfony configuration files required to bootstrap the framework. This includes \config/bundles.php\ to register core bundles (such as Doctrine, Security, and Twig) and their environment scopes, \config/services.php\ to enable autowiring and autoconfiguration for the \App\ namespace, \config/preload.php\ to optimize production performance, and \config/reference.php\ which provides IDE autocompletion for service definitions.
config · high confidence
Initial account management command handlers
This change introduces the application-layer command handlers for core account lifecycle operations. Users can now create, update, delete, block, and unblock accounts, as well as sign in and out. The implementation includes command objects with validation (email, password strength, UUIDs), handlers that interact with the account repository and password hasher, and JWT-based authentication flows for signing in and out.
src/Application/Command · high confidence
Initial application kernel setup
The application now includes a base Kernel class (src/Kernel.php) extending Symfony's BaseKernel and utilizing the MicroKernelTrait, establishing the core entry point for the Symfony framework.
src · high confidence
Initial database schema for the account entity
The application now includes the initial database migration to create the 'account' table. This table stores user credentials and profile data, including email, password, locale, roles, and status, along with timestamps for creation, updates, and soft deletion. A unique index on the email column ensures that each active account has a distinct email address.
src/Infrastructure/Doctrine/Migration · high confidence
Initial domain model for account management and localization
This change introduces the core domain entities for the application's account system, including the Account aggregate root with its lifecycle methods (create, register, activate, block, unblock, delete) and status transitions. It also adds supporting value objects and enums such as AccountIdentifier, AccountRole, AccountRoleSet, AccountStatus, and LocaleCode (supporting en-US and uk-UA), along with the AccountRegisteredEvent to track registration actions.
src/Domain/Account · high confidence
Initial implementation of Doctrine-based Account persistence
This change introduces the initial infrastructure for managing user accounts using Doctrine ORM. It adds an \AccountEntityMapper\ to convert between domain \Account\ objects and Doctrine \AccountEntity\ records, and an \AccountEntityRepository\ that implements \AccountRepositoryInterface\. The repository provides capabilities to find accounts by ID or email, search with pagination and filtering, ensure email uniqueness, and save accounts with optimistic locking and soft-delete support.
src/Infrastructure/Doctrine/Repository · high confidence
Initial implementation of Lcobucci JWT access token infrastructure
This change introduces the initial implementation of the JWT access token system using the Lcobucci library. It adds the core infrastructure components in the \src/Infrastructure/Adapter/Lcobucci\ directory, including \JwtConfigurationBag\ for managing signing keys, issuers, and validation constraints (supporting both symmetric HMAC and asymmetric RSA algorithms), \JwtAccessTokenIssuer\ for generating signed tokens with configurable lifetimes and user roles, \JwtAccessTokenParser\ for validating and decoding tokens into \JwtAccessToken\ value objects, and supporting classes like \JwtRegisteredClaims\ and exception handlers. This provides the foundational capability to issue and verify JWT-based access tokens within the application.
src/Infrastructure/Adapter/Lcobucci · high confidence
Introduction of Account Domain Contracts
New interfaces have been added to the Account domain to define core abstractions for account management and security. The AccountPasswordHasherInterface specifies the contract for hashing plain passwords into secure hashes, utilizing PHP's SensitiveParameter attribute for security best practices. The AccountRepositoryInterface defines the data access layer, providing methods to find accounts by ID or email, save account entities, and ensure email uniqueness, along with support for paginated searches by criteria.
src/Domain/Account/Contract · high confidence
Introduction of application-layer contract interfaces
The application layer now exposes a set of new interfaces in the \src/Application/Contract\ directory to define clear boundaries for core capabilities. These include \AuthorizationTokenStorageInterface\ for managing token identifiers and expiration, \JwtAccessTokenIssuerInterface\ and \JwtAccessTokenRevokerInterface\ for JWT lifecycle management, and \CommandMessageBusInterface\ alongside \QueryMessageBusInterface\ to standardize command and query dispatching. Additional contracts such as \FailedMessageCounterInterface\, \HttpbinResponseProviderInterface\, \TwigTemplateRendererInterface\, and \UuidIdentityGeneratorInterface\ provide abstractions for error tracking, external HTTP responses, template rendering, and unique ID generation, respectively.
src/Application/Contract · high confidence
Introduction of base controller with CQRS message bus injection
A new AbstractController class has been added to the presentation layer, extending Symfony's base controller. This class injects CommandMessageBusInterface and QueryMessageBusInterface via its constructor, providing a standardized foundation for controllers to interact with the application's CQRS message buses.
src/Presentation/Controller · high confidence
Introduction of dedicated message bus implementations for commands, queries, and events
The application now includes specific infrastructure classes for handling different types of messages via Symfony Messenger. CommandMessageBus and QueryMessageBus enforce that exactly one handler processes the message, throwing a LogicException if multiple handlers are detected, while EventMessageBus silently ignores events that have no registered handlers. All three buses are configured as lazy services and autowired to their respective Symfony Messenger buses (command.bus, query.bus, event.bus).
src/Infrastructure/Messenger/MessageBus · high confidence
Introduction of domain foundation utilities for immutability and event handling
This change introduces three new components to the domain foundation layer to support robust domain modeling. The ImmutableCloneTrait provides a private withFields method that leverages PHP 8.2's clone with expression to create modified copies of objects, establishing a base for immutability. The DomainEventsTrait builds on this by adding a withEvents method (marked with \#\[NoDiscard\] to prevent ignored side-effects) for appending domain events to an entity, along with a releaseEvents method to retrieve them. Additionally, a new SearchResult class is added as a readonly value object to standardize the structure of paginated search results, containing items, totalCount, pageNumber, and pageSize.
src/Domain/Foundation · high confidence
Introduction of foundational domain value objects
The domain foundation layer now includes four new value objects to enforce type safety and validation for core data types. AbstractUuidIdentifier provides a base for UUID-based identifiers with strict format validation. DateTimeUtc ensures all datetime operations are handled in UTC, offering methods to create instances from the current time, existing interfaces, or convert to standard formats. EmailAddress validates and normalizes email strings, ensuring consistent lowercase storage and equality checks. PasswordHash validates that stored hashes conform to either Bcrypt or Argon2 formats, preventing invalid hash storage.
src/Domain/Foundation/ValueObject · high confidence
Introduction of health check domain models
Added the core domain models for the health check feature: the \HealthStatus\ enum, which defines the 'ok' state and provides a string representation, and the \Healthcheck\ value object, which encapsulates the status and includes a static factory method to create a healthy instance.
src/Domain/Healthcheck · high confidence
Introduction of token storage and password hashing infrastructure
This change introduces new infrastructure components for security handling. The \AuthorizationTokenStorage\ class now implements the \AuthorizationTokenStorageInterface\, providing methods to retrieve the current token identifier, token expiration time, and user identifier by interacting with Symfony's \TokenStorageInterface\ and validating against \TokenAuthenticatedUser\. Additionally, the \AccountPasswordHasher\ class implements \AccountPasswordHasherInterface\, utilizing Symfony's \PasswordHasherFactoryInterface\ to hash plain passwords into \PasswordHash\ value objects for \PasswordAuthenticatedUser\ instances.
src/Infrastructure/Security/TokenStorage · high confidence
JWT access token authentication handler added
A new \JwtAccessTokenHandler\ class has been introduced in the security infrastructure to handle JWT-based access tokens. This component implements Symfony's \AccessTokenHandlerInterface\, parsing incoming tokens via \JwtAccessTokenParser\ and validating them against a revocation list before generating a \UserBadge\ for the authenticated user session.
src/Infrastructure/Security/AccessToken · high confidence
New HTTP exception classes for request validation errors
Added two new exception classes, RequestExtraParamsException and RequestParamTypeException, to the HTTP kernel infrastructure. These exceptions are designed to handle specific request validation failures: the former signals when a request contains unexpected parameters, and the latter indicates when parameters have invalid types. Both are configured to return an HTTP 422 status code and expose detailed constraint violation information to assist in debugging or client-side error handling.
src/Infrastructure/HttpKernel/Exception · high confidence
New HTTP kernel event listeners for correlation IDs, security headers, and exception handling
This change introduces four new Symfony event listeners in the infrastructure layer to enhance request/response handling. The CorrelationIdEventListener injects an X-Correlation-Id header into responses for traceability, while the SecurityHeadersEventListener adds X-Content-Type-Options and X-Frame-Options headers to improve security posture. The KernelExceptionEventListener standardizes error responses by normalizing exceptions, determining HTTP status codes via attributes or interfaces, and logging detailed context. Additionally, the RequestPayloadEventListener normalizes incoming request data and stores it in request attributes for downstream use.
src/Infrastructure/HttpKernel/EventListener · high confidence
New PHP CodeSniffer standards configuration
The project now includes a custom PHP\_CodeSniffer standard under \config/markup/Standards\ to enforce code style and structural rules. This configuration introduces sniffs that restrict allowed PHPDoc annotation tags, enforce strict namespace usage patterns within the \App\ hierarchy, and require explicit type hints for method parameters and return values. It also mandates strict equality operators (\===\/\!==\), requires postfix increment/decrement operators, discourages the use of \else\ statements, and automatically removes unused \use\ imports. Formatting rules enforce trailing commas in multi-line structures, prefer single-quoted strings where possible, and restrict extra whitespace and consecutive empty lines.
config/markup/Standards · high confidence
New authentication API endpoints for account management
The application now exposes a new set of RESTful endpoints under the /auth path to handle user lifecycle and session management. Users can create new accounts via POST /auth/signup (accepting email, password, and locale), authenticate to receive a Bearer token via POST /auth/signin, and invalidate their session via POST /auth/signout. Additionally, authenticated users can retrieve their current account details (ID, email, locale, status, roles, timestamps) via GET /auth/me. These controllers are wired to the application's command and query buses, enforcing full authentication for account retrieval and sign-out operations.
src/Presentation/Controller/Auth · high confidence
New console commands for log management and demo execution
Two new Symfony console commands have been added to the application. The \logs:clear\ command allows users to delete the log file for the current environment, providing feedback on success or failure. The \app:symfony:run\ command serves as a demo tool that iterates through slides from an HTTP response, with an optional \--delay\ argument to control the speed of the progress bar.
src/Presentation/Command · high confidence
New database-backed user provider for Symfony security
A new DatabaseUserProvider has been added to the security infrastructure, implementing Symfony's UserProviderInterface to load user credentials from the database. This component retrieves account details by email address using the AccountRepository and maps them to the PasswordAuthenticatedUser object, enabling authentication against stored user data.
src/Infrastructure/Security/UserProvider · high confidence
New exception classes for Lcobucci JWT validation errors
Added two new exception classes, InvalidConfigurationException and InvalidTokenException, within the Lcobucci adapter infrastructure. InvalidTokenException is annotated to return a 401 HTTP status and provides factory methods for specific token issues such as decoding errors, invalid structure, empty content, expiration, and revocation. InvalidConfigurationException is annotated to return a 500 HTTP status and covers configuration failures like missing token signer setup or empty token subjects.
src/Infrastructure/Adapter/Lcobucci/Exception · high confidence
PayPal payment capture webhook integration
The application now supports receiving and processing PayPal payment capture webhooks. A new payload converter validates incoming webhook data and maps specific PayPal event types (completed, declined, pending, refunded, reversed) to internal domain events. The remote event consumer listens for these mapped events and, upon receiving a 'completed' payment capture, publishes a PaymentReceivedEvent to the internal message bus to trigger subsequent payment processing logic.
src/Infrastructure/Adapter/PayPal/RemoteEvent · high confidence
Scheduled monitoring for failed messenger messages
A new scheduled task has been added to the scheduler that runs every 15 minutes to monitor the messenger failed transport. When unprocessed messages are detected, the system logs an error with the specific count of failed messages, enabling operators to quickly identify and address message processing backlogs.
src/Presentation/Scheduler · high confidence
Structured serialization of HTTP requests and exceptions
The serializer infrastructure now includes dedicated normalizers for converting Symfony Request objects and Throwable exceptions into structured arrays. RequestNormalizer flattens query parameters, route attributes, and file uploads into a unified format while casting string values to appropriate types and stripping internal keys. ExceptionNormalizer converts exceptions into a consistent error response containing a generated code, message, and optional validation violations; in debug mode, it also includes the full stack trace and sensitive violation details (object and invalid value) to aid troubleshooting.
src/Infrastructure/Serializer · high confidence
Behavioural changes
Added HTTP 500 exception adapters for HTTP and template rendering failures
Two new exception classes have been introduced to the infrastructure layer to handle specific failure scenarios with standardized HTTP responses. The \HttpRequestFailedException\ (Kennethreitz adapter) and \RenderingFailedException\ (Sensiolabs adapter) both extend \RuntimeException\ and are annotated with \\#\[WithHttpStatus(statusCode: 500)\]\, ensuring that when these exceptions are thrown, the application automatically returns a 500 Internal Server Error status. Each class provides a static \fromException\ factory method to wrap a previous throwable with a descriptive message ('Httpbin responder encountered an exception.' or 'Template renderer encountered an exception.' respectively), allowing callers to preserve the original error context while signaling a server-side failure to the client.
src/Infrastructure/Adapter/Kennethreitz/Exception, src/Infrastructure/Adapter/Sensiolabs/Exception · high confidence
Custom styling for Swagger UI documentation view
The template for the Swagger UI documentation page has been customized to adjust the visual presentation. The header is now hidden, and specific font sizes and weights are applied to improve readability of API endpoints and parameters. Additionally, margins around the information container and body have been adjusted to provide a tighter layout.
src/Presentation/Resource/Template/bundles/NelmioApiDocBundle · high confidence
Test coverage
Added functional tests for account management and authentication endpoints; Added test bootstrap configuration; Added test fixtures for various account states; Added test support traits for database, HTTP, and messaging; Initial unit test coverage for core domain and infrastructure components.
Dependencies
Initial project setup with Symfony 8.1 and Doctrine 3
The application is initialized as a Symfony 8.1 project, establishing the core framework dependencies (symfony/framework-bundle, symfony/console, etc.) and requiring PHP 8.5. It integrates Doctrine ORM 3.7 and Doctrine DBAL 4.4 for database management, alongside AMQP and Redis extensions for messaging and caching. Development tooling includes PHPUnit 13.3, PHPStan 2.2, and PHPCS 4.0 to ensure code quality and testing standards.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 68 → 66 (-2.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 100 (+0.9)
- Architecture 72 → 65 (-7.2)
- Maturity 62 → 60 (-1.8)
- Readiness 65 → 69 (+4.6)
- Security 77 → 84 (+7.1)
- Domain Modelling 100 → 74 (-25.6)
Resolved (22)
- Change coupling clique: BlockAccountByIdController.php, CreateNewAccountController.php, DeleteAccountByIdController.php, GetAccountByIdController.php, GetAccountsByCriteriaController.php, UnblockAccountByIdController.php, UpdateAccountByIdController.php, GetSigninAccountController.php, SigninIntoAccountController.php, SignupNewAccountController.php, GetHealthStatusController.php (src/Presentation/Controller/Account/BlockAccountByIdController.php)
- Change coupling: AnnotationTagSniff.php ↔ TrailingCommaMultilineSniff.php (config/markup/Standards/Sniffs/Annotations/AnnotationTagSniff.php)
- Change coupling: CreateNewAccountCommandHandler.php ↔ SignupNewAccountCommandHandler.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
- ClassStructureSniff.process (cognitive 18) (config/markup/Standards/Sniffs/Classes/ClassStructureSniff.php)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (src/Infrastructure/Doctrine/Repository/Account/AccountEntityRepository.php)
- Duplicated block (7 lines × 2) (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
- Duplicated block (9 lines × 2) (src/Infrastructure/Doctrine/Fixture/AccountFixture.php)
- Duplicated block (9 lines × 2) (src/Infrastructure/Messenger/MessageBus/CommandMessageBus.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- No exposed public API
- Secret: generic-api-key (.env)
- Secret: generic-api-key (.env)
- …and 2 more
New (60)
- Change coupling clique: CreateNewAccountCommand.php, SignupNewAccountCommand.php, UpdateAccountByIdCommand.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommand.php)
- Change coupling clique: CreateNewAccountController.php, UpdateAccountByIdController.php, SigninIntoAccountController.php (src/Presentation/Controller/Account/CreateNewAccountController.php)
- Change coupling: Account.php ↔ Healthcheck.php (src/Domain/Account/Account.php)
- Change coupling: Account.php ↔ Version20200101000000.php (src/Domain/Account/Account.php)
- Change coupling: DeleteAccountByIdCommandHandler.php ↔ SignupNewAccountCommandHandler.php (src/Application/Command/DeleteAccountById/DeleteAccountByIdCommandHandler.php)
- Change coupling: DeleteAccountByIdCommandHandler.php ↔ UpdateAccountByIdCommandHandler.php (src/Application/Command/DeleteAccountById/DeleteAccountByIdCommandHandler.php)
- Change coupling: GetAccountByIdQueryResult.php ↔ GetAccountsByCriteriaQueryResult.php (src/Application/Query/GetAccountById/GetAccountByIdQueryResult.php)
- Change coupling: GetAccountByIdQueryResult.php ↔ GetSigninAccountQueryResult.php (src/Application/Query/GetAccountById/GetAccountByIdQueryResult.php)
- Change coupling: GetAccountsByCriteriaController.php ↔ GetSigninAccountController.php (src/Presentation/Controller/Account/GetAccountsByCriteriaController.php)
- Change coupling: GetSigninAccountController.php ↔ GetHealthStatusController.php (src/Presentation/Controller/Auth/GetSigninAccountController.php)
- Change coupling: HttpbinResponseProvider.php ↔ TwigTemplateRenderer.php (src/Infrastructure/Adapter/Kennethreitz/HttpbinResponseProvider.php)
- Change coupling: PasswordAuthenticatedUserChecker.php ↔ DatabaseUserProvider.php (src/Infrastructure/Security/AuthenticatedUser/PasswordAuthenticatedUserChecker.php)
- Change coupling: SignupNewAccountCommandHandler.php ↔ UpdateAccountByIdCommandHandler.php (src/Application/Command/SignupNewAccount/SignupNewAccountCommandHandler.php)
- Change-coupling hub: BlockAccountByIdCommandHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UnblockAccountByIdCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetSigninAccountQueryHandler.php (src/Application/Command/BlockAccountById/BlockAccountByIdCommandHandler.php)
- Change-coupling hub: CreateNewAccountCommandHandler.php → DeleteAccountByIdCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php (src/Application/Command/CreateNewAccount/CreateNewAccountCommandHandler.php)
- Change-coupling hub: GetAccountByIdController.php → GetSigninAccountQueryResult.php, GetAccountsByCriteriaController.php, GetSigninAccountController.php (src/Presentation/Controller/Account/GetAccountByIdController.php)
- Change-coupling hub: GetAccountByIdQueryHandler.php → BlockAccountByIdCommandHandler.php, CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UnblockAccountByIdCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetAccountsByCriteriaQueryHandler.php, GetSigninAccountQueryHandler.php (src/Application/Query/GetAccountById/GetAccountByIdQueryHandler.php)
- Change-coupling hub: GetSigninAccountQueryHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php (src/Application/Query/GetSigninAccount/GetSigninAccountQueryHandler.php)
- Change-coupling hub: RenderingFailedException.php → TwigTemplateRendererInterface.php, HttpbinResponseProvider.php, InvalidTokenException.php (src/Infrastructure/Adapter/Sensiolabs/Exception/RenderingFailedException.php)
- Change-coupling hub: UnblockAccountByIdCommandHandler.php → CreateNewAccountCommandHandler.php, DeleteAccountByIdCommandHandler.php, SigninIntoAccountCommandHandler.php, SignupNewAccountCommandHandler.php, UpdateAccountByIdCommandHandler.php, GetSigninAccountQueryHandler.php (src/Application/Command/UnblockAccountById/UnblockAccountByIdCommandHandler.php)
- …and 40 more
Changes since last survey
- 44 commits — 44 feature/other, 0 fixes
By area
- (root) — 30 commits
- src/Infrastructure — 8 commits
- src/Presentation — 2 commits
- config/packages — 1 commit
- config/reference.php — 1 commit
- src/Application — 1 commit
- tests/Functional — 1 commit
Notable commits
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- change: Initial commit
- …and 24 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
opifex/symfony was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 8e662778031cd416b7f0dc58c8a572973c8e328a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.